A security operations team implements a security orchestration, automation, and response (SOAR) platform. Which primary benefit does SOAR provide over a traditional SIEM alone?
Select an answer to reveal the explanation.
Short Explanation and Infographic
Here's the deal — b is correct because SOAR's primary value is automating the repetitive, time-consuming manual steps in incident response (IP reputation lookups, user account lookups, automated blocking, ticket creation) through playbooks, dramatically reducing mean time to respond. A is wrong because SOAR is not primarily a log storage platform; log storage and indexing is the SIEM's function.
Full explanation below image
Full Explanation
B is correct because SOAR's primary value is automating the repetitive, time-consuming manual steps in incident response (IP reputation lookups, user account lookups, automated blocking, ticket creation) through playbooks, dramatically reducing mean time to respond. A is wrong because SOAR is not primarily a log storage platform; log storage and indexing is the SIEM's function. C is wrong because SOAR consumes threat intelligence from feeds; it does not generate its own. D is wrong because packet capture is an NSM tool capability; SOAR focuses on process automation and case management.